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NATIONAL SECURITY AGENCY 
CENTRAL SECURITY SERVICE 

FOBT GEORGE G. MEADE. MARYLAND 207SS-6000 


12 September 2008 


MEMORANDUM FOR THE CHAIRMAN. INTELLIGENCE OVERSIGHT BOARD 


THRU: Assistant to the Secretary of Defense {Intelligence Oversight) 

SUBJECT; (U/TTWOt Report to the Intelligence Oversight Board on NSA Activities - 
INFORMATION MEMORANDUM 


(U//FOUO) Except as previously reported to you or the President, or otherwise staled in 
the enclosure, wc have no reason to believe that any intelligence activities of the National Security 
Agency during the quarter ending 30 June 2008 were unlawful or contrary to Executive Order or 
Presidential Directive and thus should have been reported pursuant to Section 1.7.(d) of Executive 
Order 12333. 


(U//I OUO; The Inspector General and the General Counsel continue to exercise oversight 
of Agency activities by inspections, surveys, training, review of directives and guidelines, and 
advice and counsel. These activities and other data requested by the Board or members of the staff 
of the Assistant to the Secretary of Defense (Intelligence Oversiglit) are described in the enclosure. 

GEORGE E^LARD 
InspectotXJti^ai, I 

VITO T. POTENZA 
General Counsel 


(U// POUO)-1 concur in the report of the Inspector General and the General Counsel and 
hereby make it our combined report. 



Lieutenant General, U. S. Army 
Director, NSA/Chief, CSS 


End; 

Quarterly Report 
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1. (U/ZPOttO)-Intelligence, counterintelligence, and intelligence-related activities 
that violate law, regulation, or policy substantiated during the quarter, as well as 
actions taken as a result of the violations. 


(U) intelligence Activities 

(b) (3)-P.L. 86-36 

(T9//9I;' KliLTO USA, FVSY) Unintentional collection against United States 
persons. This quarter, there were [~~linstances in which Signals Intelligence (SIGINT) analysts 
inadvertently collected communications to, from, or about U. S. persons while pursuing foreign 
intelligence tasking. All intercepts and reports have been deleted or destroyed as required by 
United States SIGINT Directive (USSID) SP0018. ( 1 ) 

(b)(1) (b) (3)-P.L. 86- 

(b)(3)-P.L. 86-36 (b)(3)-18 USC 7 

(b)(3)-50 USC 3024(i) l3)-50 USC 3 

sked the telephon e numbers associated with a U.S. 

_ I without verifying that consent for 

colle ction had been given by the person a nd approved by DIRNSA. Th e selectors, on coverage 
from I were detasked. I l intercepts were purged 

from data repositories | [when the mistake was found during a target review. 


(U) Unauthorized Targeting 
86-36 


(b)(3)-P.L 

■fS VS I / i rN E ^ H an NSA/CSS I l analvst targeted a foreign person in 

the United States without Attorney General authorization. She learned that a person tied to the 
I |was in the United States an d was suspected to have planned an 

operation to take place l I Thinking only of the urgency and not the 

target's location, the analyst queried an NSA database for information without seeking 
authorization to target the individual. No results were returned. The incident was found by the 
analyst’s auditor, and the analyst was counseled and received remedial training. 


resulted in the continued targeting of a U.S 


erson after hi.s consent 


to monitoring expired. 


Although the consent cxpii ed on 


NSA/CSS analysts did not remove the selector from collection until 
intercepts that were purged from NSA databases. 


There were! 


(TS//Sl/ i ^ i F) An NSA/C SS analyst task ed collection on a U.S. person before receiving Attorney 
General authorization on I I The analyst wrongly believed that authorization had 

been received. The unauthorized action resulted in the intercept of | ~~\ 

(b) (1) 

(b)(3)-P.L. 86-36 (b)(1) 

(b)(3)-P.L. 86-36 
L- 86-36 (b)(3)-18 USC 798 

S use 798 (b)(3)-50 USC 3024(i) 
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(b) (3) 


(b)(1) 

(b) (3)-P.L. 86-36 


bclweeni 

discovered 


__ Al! collected data was purged when the violation was 

Jand no reports were issued on the data. 


(U) Computer Network Exploitation (CNE) 
(T0//0l'/RCL- TO USjV. rV fe¥»f 


■(b) (1) 

(b) (3)-P.L. 86-36 
(b) (3)-ie use 798 
(b)(3)-50 use 3024(i) 



(U) Database Queries '(b) (i) 

(b)(3)-P.L. 86-36 

TO USA, rVEY) There werc l [ instances of unintentional co: 
from poorly constructed database queries. All results were deleted from the 


lection resultini’ 


-p 


(U) U.S. Person Status 

,L. 86-36 


(b).U) 
(b) ('St- 


P.L. 86-36 


fl'S//Sl//t'J!') On l l oc casions, targets initially thoug ht to be legitimate and foreign were found 


ight 

JN‘ 


NSA terminated targetingf 


to hold U.S. cit izenship. 

when thc | Relay ed that the target held a U.S. pas.sport. Collection was purged from 
databases, and | I rcports were cancelled. I ‘ I sclc ctor wa s not detasked 

when U. S. person .status was suspected. The d ctaskiim failure resulted in i K nterccots 
between I i when the se lectors were positively linked to an 

I _ i The selectors were deta.sked, 

collection was purged! 

col 


vetting inadvertent collection. 
(T0//01//> i lf) l 


and NSA/CSS analysts were retrained on the process for 

.'(b) (1) 

(b)(3)-P.L. 86-36 

InSA/C SS analysts targeted U.S. persons. 


did not realize that the^ 


the analyst searched for a U.S. 


I was owned by a U.S. company. 
the analyst did not follow research procedures, which required him to chcckf 


Ja raw traffic database because he 


occurred when another analyst failed to review 


Queries were tenninated, and results were not retained. 


mistakes were lound dunng the auditing and oversight functions, and the analysts were retrained 
on search procedures. 


? 


(b)(3)-P.L. 86-36 


(TS/j'SI/i ' N F^oliection transcriptionf 


was usexl by a U.S. Government employee onL 


1 revealed th;U a 


J The transcript noted a 


conversation between two U.S. Government employees. When NSA/CSS learned of the 
incidental collection, minimization procedures were applied as directed by the USSID SPOOl 8. 

(b)(1) 

(b) (3)-P.L. 86-36 

(b)(3)-P.L. 86-36 (b)(3)-18 USC 798 

(b)(3)-18 USC 798 
(b)(3)-50 USC 3024(i) 
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(3//3f//llLL TO UOA, rvCV) | l a valid foreign target! 

the United States. Tasking was terminated, and collection was purged from NSA databases. No 
reports were issued. 

\b) ( 1 ) 

(U)De.asking Delays W(ai-a.L. »6-36 


mLL 1U ubA, 1 VLVj _ h he United States on 

I selectors attributed to a tareet were deta.sked on I I however □ 

[:lid not detask I [ Research is ongoing to isolate t he cause of the 

I The inte rcept associated w ith the I 

he United States was purged from NSA databases! I - 

'-' (b)(1) 

Foreign Intelligence Surveillance Court (FlSC)-Authorized CoH^tionlb) ( 3 )-so^iisc^soL (i) 


anNSA/CSS analyst discovered a FlSC-authorized selector 


associated with a torcign 


had not heen rcniovcd from l askint! 


Pursuant to the FISC order, detasking 


However, a problem 

_^^rcvcnied the execution of the action. When the 

_a review of target selectors was conducted. | | 

additional selectors affected by die system problem were removed from tasking. 


(S/(S l //P . liLTO ur.A, I VFV) Unintentional dissemination of U.S. identities. There 
were] jinstanccs in which SIGINT analysts disseminated communications to, from, or about 
U.S. persons while pursuing foreign intelligence tasking this quarter. All data have been deleted 
or destroyed as required by USSID SPOOl 8. <11 

(b)(3)-P.L. 86-36 

(3//31/VRCL ro USA, FVCi’) During this quarter, |~~|S1GJNT products were cancelled because 
they contained the identities of U.S. persons, organizations, or entities. In all instances, the 
reports were cither not reissued or were reissued with proper minimization. 


I durin g a review of interceptf 

discovered mat the [from a le gitimate foreign 

)n the United States from i i{ ~| was notified and 

intercepts for the timeframe the target was in tlie United States. 


(b)^>P.L. 86-36 
(b)(3)-18USC 798 
(b)(3)-50 use 3024(i) 


estroyed the 


(U//F0Wf Dissemination of Foreign Intelligence Surveillance Court (FISC)-Authori 2 ed 
Collection 


NSA/CSS analyst tipped information on | j 
^intercepts to other SIGINT analysts using a communication 


(b) (1) 

(b) (3)-P.L. 86-36 
(b) (3)-50 use 3024(i) 
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(b)(1) 

(b)(3)-P.L. 86-36 
(b)(3)-50 use 3024(i) 



tool that was not authorized as a dissemination tool fo H [ data because the c hat too 

not have the ability to track U.S. person inf'onnation. When recognized "~] the dat 

deleted. Although not a violation of the FISA and related authorities, the practice does not 
provide an audit trail of the U.S. person information passed to others within the SIGINT 
production chain. The process for using the chat tool was amended! 


lerson was not masked 


(U) The Protect America Act of 2007 (PAA) "(b) (i) 


<£//CliVMFtOn|_[occasions. NS A/CSS analysts did not purge PAA-related collection from 

NSA databases in a timely manner.} Ian email selector of a legiti mate foreign 

target was detasked becaus e | j Although 

the database p urging begani Icollectio n from the j ( databases was not 

removed u ntil} ~ I yiothcr target s elector was del 

purging of ] [ databases was not completed until \ Lastly, I 

target selector was d etasked. but the data was not completely purged from the 

until I I 


■databases 


lb)(1) 

(b) {3)-P.L. 66-36 
(b){3)-50 use 3024(i) 


(U) Counterintelligence Activities 


(U) Nothing to report, 


(U) Intelligence-related Activities 


(J/V3L7REL TO UGA, r \^CV) Although not violations of E.O. 12333 and related directives, 
NSA/CSS reports ! l instanc es in whic h database access was not terminated when the need for 
access was no longer required. ! ! acccss to FISA data was not t erminated when the 
NSA/CSS employees transferred or forward-deployed to locations in } ! and 

joccasions. a ccess to PAA data was not terminated when NSA./CSS analysts 
1 Once identified, accesses were revoked. 


deployed to 


4 
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(U) Destruction Delays 


(TOZ/Q I/;?j r') I \ nadverten t intercepts collected from 

J)ut ihc analyst forgot to! 

si^ 


productioli staff found the oversi^it[ 


were purged 


. The NSA analysis and 
]at which time the collection was deleted. The 


analyst reviewed the procedures for purging collection to lessen the possibility of a recurrence of 
a retention violation. b) (l) 

. .{b)(3)-P.I 

(TS//SI//hiF) On I t iccasions. NS^ VCSS analysts did n ot purge unintentional collection from 

NSA databases in a timely ma nner. I Ian email select or for a legitimate 


foreign target was detasked on , 

Collection was not removed from thc| [data repositories until 


pn the United States. 


] 


but collection was not purged from thej 


the selector for a different taruct was detasked on 


^databases until 


2. (U//FOUO) NSA/CSS OIG Intelligence Oversight inspections, Investigations, 
and Special Studies. 


(U/'TOUCT) During this quarter, the Office of Inspector General reviewed various intelligence 
activities of the NSA/CSS to determine whether they had been conducted in accordance with 
applicable statutes. Executive Orders, Attorney General procedures, and Department of Defense 
and internal directives. With few exceptions, the problems uncovered were routine and showed 
that operating elements understand the restrictions on NSA/CSS activities. 


(U/y^'OUO) NSA/CSS Hawaii. The inspection found non-compliance in the completion of 
initial and annual refresher intelligence oversight training and the database to track training 
for those with access to SIGINT databases and their auditors was not accurate. In a future report, 
the NSA/CSS Inspector General will update actions taken by NSA/CSS Hawaii to correct the 
inspection findings. A highlight of the inspection was the| Idatabase and Standard 

Operating Procedure (SOP) developed by \ 

The SOP has reduced the detasking time from | [ minutes and has helped prevent 

collection violations. 


(b) (3)-P.L. 


(U//rOUO) NSA/CSS Colorado. The inspection found non-compliance in the completion of 
initial and annual refresher intelligence oversight training. NSA/CSS Colorado lacked a process 
to track training for employees with access to NSA databases and had no processes to update the 
data. Operations employees displayed a good understanding of the intelligence oversight 
authorities in relation to collection, minimization and dissemination. 


3. (U) Substantive Changes to the NSA/CSS Intelligence Oversight Program. 

(U) Notliing to report. 


. 86-36 


86-36 


TOP SnORCT//COMn»lT/MOFOR?^ 
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4. (U) Changes to NSA/CSS published directives or policies concerning 
intelligence, counterintelligence, or intelligence-related activities and the reason 
for the changes. 

(U) Nothing to report. 

5. (U) Procedures governing the activities of Department of Defense (DoD) 
Intelligence components that affect U.S. persons (DoD Directive 5240.1-R, 
Procedure 15) Inquiries or Matters Related to Intelligence Oversight Programs. 

(U) Nothing to report. 


iOft SS eR£T//CQMIKT//?(Or()R>v' 
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